Last updated: July 14, 2026
Summary: Simple Authenticator stores your 2FA account secrets on your device. Login is optional. If you enable cloud backup, only ciphertext encrypted with your sync passphrase is stored in the cloud — we cannot read your codes. The free app may show ads via Google AdMob.
Simple Authenticator is a TOTP/HOTP authenticator (two-factor verification codes). It is not a password manager and does not store website passwords or login vaults.
Accounts you add (issuer, account name, OTP secret, algorithm settings) are stored locally using platform secure storage (e.g. Android Keystore / iOS Keychain via the app’s secure storage layer).
Optional local settings may include PIN lock preference, biometric unlock preference, auto-lock timeout, and whether you skipped sign-in.
OTP codes are generated on-device from your secrets. They are not sent to a server as part of normal code display.
You may use the app without signing in (“Skip for now”). If you choose to sign in:
Passkey sign-in (where available) is an alternate way to authenticate to the app’s cloud identity, not a vault of website passkeys.
Optional PIN, biometric unlock, and auto-lock protect access to the app on your device. Biometric data stays on the device and is handled by the operating system.
Encrypted file export/import uses a separate file passphrase you choose. Exported files leave the app only when you share or save them through the system share sheet or file picker.
You can also import accounts from Google Authenticator migration QR codes or related import flows you initiate.
The app may display banner ads using Google Mobile Ads (AdMob). Ad networks may collect device and usage signals according to Google’s advertising policies and your OS-level privacy settings (for example App Tracking Transparency on iOS, or Google Play advertising ID controls on Android).
These providers process data under their own privacy policies when you use features that depend on them.
Material changes may be reflected in app or website updates. Continued use after an update means you accept the revised policy.
Questions? Visit our Support page.